首页> 外国专利> PROACTIVE SYSTEM AGAINST MALICIOUS PROCESSES BY INVESTIGATING THE PROCESS BEHAVIORS AND A METHOD THEREOF

PROACTIVE SYSTEM AGAINST MALICIOUS PROCESSES BY INVESTIGATING THE PROCESS BEHAVIORS AND A METHOD THEREOF

机译:通过研究过程行为来预防恶意过程的预防系统及其方法

摘要

PURPOSE: A proactive system against malicious processes by investigating the process behaviors is provided to accurately determine a malicious process by considering the state information of a process.;CONSTITUTION: A system call hooker(31) hooks a system call of an OS(Operating System). A system call storage(32) checks the process which request the system call and stores the system call request information as request information about the request process. A malicious process determiner(33) determines a distrust behavior of the system call request under the determination condition. The determination condition is composed of conditions which uses the request information of the hooking system call as variables. If the request of the system call is determined as a distrust behavior, a malicious process processor(34) blocks the request of the system call.;COPYRIGHT KIPO 2012
机译:目的:提供一种通过调查进程行为来防御恶意进程的主动系统,以通过考虑进程的状态信息来准确地确定恶意进程。;构成:系统调用挂钩(31)挂钩OS(操作系统)的系统调用)。系统调用存储器(32)检查请求系统调用的过程,并将系统调用请求信息存储为关于请求过程的请求信息。恶意进程确定器(33)在确定条件下确定系统调用请求的不信任行为。确定条件由将挂钩系统调用的请求信息用作变量的条件组成。如果系统调用的请求被确定为不信任行为,则恶意进程处理器(34)阻止该系统调用的请求。; COPYRIGHT KIPO 2012

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号